CVE-2020-23912: Null Pointer Dereference
An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-23912?
CVE-2020-23912 has been classified as a high severity vulnerability due to its potential to cause Denial of Service.
How does CVE-2020-23912 work?
CVE-2020-23912 exploits a NULL pointer dereference in the AP4_StszAtom::GetSampleSize() function, leading to application crashes.
Which versions of Bento4 are affected by CVE-2020-23912?
Bento4 versions up to and including 1.6.0-637 are affected by CVE-2020-23912.
How can I mitigate CVE-2020-23912?
To mitigate CVE-2020-23912, upgrade Bento4 to a version later than 1.6.0-637 where the vulnerability is resolved.
Is there a patch available for CVE-2020-23912?
Yes, a patch for CVE-2020-23912 is available in the newer versions of Bento4, which users should apply immediately.